Voraxx MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SHODAN_API_KEY | No | If set, shodan_host_lookup uses the full Shodan Host API instead of the free InternetDB endpoint | |
| VORAXX_MCP_HTTP_TIMEOUT | No | Timeout (seconds) for outbound HTTP lookups | 10 |
| VORAXX_MCP_OSV_BASE_URL | No | Override the OSV.dev base URL (mainly for testing) | https://api.osv.dev |
| VORAXX_MCP_SHODAN_API_URL | No | Override the Shodan Host API base URL (mainly for testing) | https://api.shodan.io |
| VORAXX_MCP_SHODAN_INTERNETDB_URL | No | Override the InternetDB base URL (mainly for testing) | https://internetdb.shodan.io |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| cve_lookupA | Look up a CVE by ID (e.g. CVE-2021-44228) against the free, keyless OSV.dev vulnerability database. Returns summary, CVSS, affected packages, and references. Read-only; no API key required. |
| shodan_host_lookupA | Look up recon data (open ports, hostnames, CPEs, known CVEs) for an IP address. Uses Shodan's free InternetDB endpoint by default (no API key needed); if the SHODAN_API_KEY environment variable is set, uses the full Shodan Host API instead. Read-only -- reflects Shodan's last scan, not a live probe. |
| nuclei_scanA | Run a scan against a target using nuclei (ProjectDiscovery), if nuclei is installed locally on this machine. Orchestrates your own nuclei binary and templates only -- this tool does not bundle or download any scan templates itself. Only scan systems you are authorized to test. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
Each tool targets a distinct operation: CVE lookup for vulnerability details, nuclei for active scanning, and Shodan for passive reconnaissance. No overlap in purpose.
All tool names follow the pattern '{source}_{action}' with consistent lowercase and underscores. Verbs 'lookup' and 'scan' are appropriate and distinguishable.
Three tools is a focused, well-scoped set for a security reconnaissance server. Each tool provides essential functionality without bloat.
The set covers vulnerability lookup, active scanning, and passive recon, covering key security workflows. A minor gap might be a tool for detailed port scanning, but the current set is sufficient for most common tasks.